forumNew topic

An employee's personal phone got hacked and has company data on it — what should we do immediately?

AAslı A***MemberCommunity member
Joined
Oct 2023
Message
19
#1

We are a 14-person architecture and project consulting firm based in Berlin. Our employees use their own smartphones to view drawings and reply to emails out in the field (BYOD). This morning our site manager called in a panic; he said that after clicking a parcel tracking link sent to his phone, unauthorized actions started running on the device, and his banking and email apps kept throwing security alerts back-to-back.

The device had our company email account, our cloud storage, and sensitive technical specifications for an ongoing public tender worth 180.000 EUR on it. The employee's personal photos and private data are on the same phone as well. Operationally and legally, what exact steps should we take in these first few hours? Is it the right call to wipe the device remotely, or should we secure the other accounts first?

PPınar U***MemberCommunity member
Joined
Mar 2023
Message
188
Most Helpful#2

Short answer: Your very first step is definitely not wiping the device; it's immediately revoking the device's access to company accounts from the main server. A direct factory reset destroys forensic evidence and could trigger legal disputes over the employee's personal data, so the process must start by terminating active account sessions.

Follow these steps within the first 60 minutes: Revoke all active sessions for the affected user via the admin console, change the corporate email and cloud passwords, remove any registered multi-factor authentication (MFA) devices, and temporarily suspend the account. Then have the employee turn off cellular data and Wi-Fi, and put the device into airplane mode.

Regarding a remote wipe, look at your existing setup: If you are using mobile application management (MAM) or a work profile, perform a selective wipe to remove only corporate data and the work profile. Wiping the entire device carries legal risk without prior explicit consent, as it wipes out their personal data.

Start an incident log right away. Check the server audit logs to see which files were downloaded and which unfamiliar IP addresses accessed the account. Under German data protection law (DSGVO Article 33), if there is a likelihood that third-party sensitive data was compromised, you need an assessment done for the mandatory 72-hour notification window.

AAlperMember
Job title
Field sales manager
Organization type
cooperative
Joined
Mar 2024
Message
102

Doki · E-commerce infrastructure · 2026

#3

Have the employee put the phone into airplane mode immediately and pull the SIM card out. Suspicious SMS malware might be reading texts in the background to steal incoming 2FA codes. Any password resets you do from a PC could be compromised if you don't cut off incoming SMS traffic first.

HHakan A***Member
Job title
Software team lead
Sector
Catering
Organization type
20-person company
Joined
Oct 2023
Message
86
#4

Check the OAuth permissions on your email server. The malware might have grabbed a persistent API token through the mail client on the device. Even if you change passwords, if an unfamiliar third-party app is authorized, access will persist.

YYavuz B***Member
Job title
Human Resources Specialist
Sector
Leather
Organization type
120-person company
Joined
Mar 2024
Message
5
#5

Under DSGVO, the 72-hour notification clock starts the moment the breach is discovered. Check whether the technical specs contain personal data, and review the data protection agreement with the public agency running the tender. If the risk is high, you'll need to submit a preliminary notification to the state data protection commissioner (Landesdatenschutzbeauftragter).

HHasan K***ExpertCommunity member
Joined
Apr 2025
Message
214
#6

Last year one of our architects had their account compromised in a similar phishing scam. We killed all sessions within the first 2 hours, and the audit logs showed they only pulled 3 emails from the inbox. We spent 1.400 EUR on an external forensic investigation, but the data authority didn't issue any fines.

OOrhan T***MemberCommunity member
Joined
Mar 2024
Message
242
#7

First 3 hours checklist: 1) Isolate the device from the network (airplane mode and pull the SIM), 2) Revoke all sessions from the admin console and reset password/MFA, 3) Export cloud download logs for the last 24 hours, 4) Warn the rest of the company about the SMS scam.

TTolga T***Member
Job title
Software developer
Sector
Livestock
Organization type
a company within a holding
Joined
Jun 2023
Message
1
#8

Did the employee have a separate work profile (sandbox) configured for company email or was it set up via IMAP directly in the stock mail app? Is it Android or iOS? Those details are critical to figuring out whether data actually leaked.

HHakan K***MemberCommunity member
Joined
Oct 2022
Message
84
#9

do we need to changge the shared office Wi-Fi password too? the employee was connected to the office network yesterday with that phone could the other computers there be infected?

MMustafa S***Member
Job title
Human Resources Manager
Sector
Jewelry
Organization type
two-branch business
Joined
May 2024
Message
43
#10

if u don't have a byod policy do not remotely wipe the whole phone then last year a friend of mine did a full wipe on a staff member's phone, employee went to labor coourt claiming their kid's wedding photos were gone and won the case.

VVildan T***Member
Job title
Export manager
Sector
Cosmetics
Organization type
120-person company
Joined
Oct 2022
Message
64
#11

Don't miss this: Most time waste accumulates in tasks waiting for approval.

Just leaving this note, it might be useful.

HHaticeMember
Job title
Family business
Organization type
boutique agency
Joined
Jun 2024
Message
86
#12

I didn't know that.

AAhmet N***Expert
Job title
Store associate
Sector
Construction
Organization type
a company within a holding
Joined
Jul 2022
Message
153
#13

I have a question, don't want to go off-topic though. The biggest time-waster for us was not knowing who had the final say.

That's all, sorry if I went on too long.

NNecati B***MemberCommunity member
Joined
Aug 2024
Message
19
#14

I'm in the same situation that's why I'm asking. Everything goes well for the first three months; problems arise in the fourth.

I'm also curious if anyone does it differently.

SSerdar K***Veteran
Job title
Growth marketing
Joined
May 2023
Message
264
#15

I felt relieved reading this answer, so it's not just me. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#16

I'm curious too. Processes without records never improve, because you don't know what to fix.

Correct me if I'm wrong.

GGürkan Y***MemberCommunity member
Joined
Jul 2023
Message
8
#17

I agree with this. Start with a small trial; don't commit to everything at once.

Correct me if I'm wrong.

RReyhan T***MemberCommunity member
Joined
Nov 2024
Message
318
#18

I completely agree. When we decide without measuring, we always end up in the same place.

Don't hesitate to ask; those who don't ask always pay more. Good luck with that.

TTaner K***Member
Job title
Sales Manager
Sector
Seafood
Organization type
medium-sized business
Joined
Sep 2023
Message
3
#19

Let me summarize the topic, since several different answers were given. anyway taking notes for two weeks yields better results than a six-month estimate.

Correct me if I'm wrong.

LLale U***ExpertCommunity member
Joined
Aug 2025
Message
2
#20

I'm in the same situation, that's why I'm asking. Start with a small trial; don't commit to everything at once.

Good luck with that.

Reply